Overview
Okta is an identity and access management (IAM) platform. It controls and protects user access to applications and services from one central location. Users log in to many apps with one set of credentials (SSO). IT teams control access and security from one location.
The Persona Okta integration adds identity verification to all of the employee lifecycle, from onboarding to account recovery. Identity verification helps to protect against phishing, social engineering, and deepfake attacks.
With this integration, organizations can:
- Trigger identity verification at important moments, for example onboarding, password resets, and authenticator enrollments.
- Get user profile data from Okta to add data to verification workflows.
- Automate account actions, for example resetting MFA factors or suspending users, from Okta.
This integration helps IT and InfoSec teams decrease the risk of account takeover. It makes account recovery faster. It gives employees faster and more secure access. It also helps teams keep data compliance and support distributed teams.
Integration Options
Persona offers three ways to integrate with Okta:
- Persona for Identity Verification (IDV) in Okta
- Persona’s Okta API marketplace integration
- Persona as an Identity Provider (IdP) authenticator
Only options 1 and 3 trigger identity verification. The Okta API marketplace integration is a Workflows integration. It reads Okta profile data and does account actions. You use it together with one of the two identity verification methods above. To select between options 1 and 3, read “Choosing your integration method” below.
Note: For Okta SCIM and SSO provisioning, read these articles:
Choosing your integration method
Before you configure an integration, decide which Okta policies Persona must protect.
Okta policy types
Okta has two types of authentication policies that can use Persona:
- Account Management Policies (OAMP): These policies set the authentication requirements to enroll or unenroll authenticators, reset a password, or unlock an account. Example triggers: a user clicks “Forgot password,” activates a new account, or enrolls a new authenticator.
- App sign-in policies: These policies set how a user must authenticate to access an app. Example trigger: a user signs in to Jira with SSO.
Identity Verification vs. IdP authenticator
Persona for Identity Verification (IDV) in Okta triggers identity proofing just-in-time. It starts only when an employee does an action that a policy protects. An employee who never does a protected action never sees Persona. There is no enrollment step. This method works only with OAMP.
Persona as an Identity Provider (IdP) authenticator requires an employee to enroll in Persona before an authentication policy can use it as a factor. To enroll, the employee completes an inquiry. Okta admins can make enrollment mandatory. In that case, an employee enrolls the next time they sign in. This method works with OAMP and with app sign-in policies.
The tradeoff: an employee who did not enroll in the IdP authenticator cannot use it as a factor. Password reset can require the IdP authenticator. If it does, an employee who never enrolled cannot use the “Forgot password” link to reset their password without help.
Do not protect authenticator enrollment with an Account Management Policy that requires Persona as the IdP authenticator. An employee who did not enroll yet cannot complete the enrollment that the policy protects.
Feature comparison
| Feature | Persona IDV | Persona as an IdP authenticator |
|---|---|---|
| Supported policies | Account Management Policies (OAMP) only | Account Management Policies and app sign-in policies |
| Enrollment required | No | Yes |
Which method should I use?
| If you want to protect | Use |
|---|---|
| Only Account Management Policies (password reset, authenticator enrollment, account unlock) | Persona for Identity Verification (IDV). No authenticator enrollment needed. |
| App sign-in policies (for example, requiring verification to sign in to an app) | Persona as an IdP authenticator. Only authenticators are eligible for app sign-in policies. |
| Both | Either method. Many customers start with Persona IDV for Account Management Policies. They add the IdP authenticator later, because the two methods are compatible. A customer who wants both from the start can use only the IdP authenticator. That customer must require enrollment for every employee at the start. |
You can use the two integration methods together. Both methods use the Okta user ID as the Reference ID to identify the Persona account of an employee. Both methods use the email address as a second identifier. Thus, when you start to use the second method, it uses the same accounts again and does not make duplicates.
Plans Explained
Okta Integration by plan
| Startup Program | Essential Plan | Growth Plan | Enterprise Plan | |
|---|---|---|---|---|
| Okta Integration | Not Available | Not Available | Limited | Available |